> The signer is built into the OS
Will it receive memory hardening? Zeroisation before deinitialization in particular (but ideally I'd love to see the usage of `memfd_secret`, which will make an unencrypted key impossible to write to a swap partition/file).